Techno Blog
Chronicles from the Digital Era
Chronicles from the Digital Era: Cybersecurity Watch and Expertise
Precicom / Techno Blog / Microsoft 365: Is Your Environment Truly Secure? | Webinar Recap
Sécurité
Microsoft 365: Is Your Environment Truly Secure? | Webinar Recap
Reading time:
7–8 minute read
-
28 August 2026
Microsoft 365 Security Starts With Identity
Attacks targeting Microsoft 365 environments are evolving quickly. Organizations still need to contend with ransomware and data exfiltration, but identity-related incidents and account compromises have become a central concern. During our August 27, 2026 webinar, Martin Dagnault, Director of Cybersecurity at Precicom, shared observations from the field and presented a structured approach to making a Microsoft 365 tenant more resilient.
Why does this deserve your attention? A compromised identity can provide access to email, SharePoint documents, Teams conversations, calendars and connected SaaS applications. Even when endpoints are protected, an attacker may be able to operate directly in the cloud environment by using a legitimate account.
Why a Functional Tenant Can Still Be Vulnerable
Microsoft 365 makes deployment and collaboration easier, but a functional environment is not necessarily a properly hardened one. Enabling basic controls does not replace a configuration tailored to the organization’s context.
Common gaps include:
- multifactor authentication that is enabled but relies on methods that may not always resist phishing;
- Conditional Access policies that are missing, static or overly permissive;
- insufficient detection of risky sign-ins and behaviours;
- alerts that are generated without active monitoring or a timely response;
- permissions that allow unauthorized third-party applications or rules to be added;
- insufficient logging to support an investigation;
- licences that do not provide access to required controls or, conversely, exceed actual needs.
Licensing decisions therefore affect security, compliance and cost optimization. By taking the time to review them, your organization can better understand which features are actually available, required and in use.
From a Compromised Account to an Organizational Crisis
Using a Microsoft 365 account compromise following a phishing attack as an example, Martin illustrated how an attacker can exploit account permissions, connect a third-party application, analyze the account holder’s relationships and launch highly contextualized messages.
Artificial intelligence can make these campaigns more credible and effective. It can help segment recipients, tailor messages, manage replies and reproduce the compromised person’s business context. The attack can then extend beyond the original account and affect employees, customers and partners.
Technical recovery can be relatively quick when the right logs and processes are available. It may include resetting the password and multifactor authentication, revoking sessions, removing malicious applications and rules, and reviewing sign-ins. The organizational consequences, however, can last much longer.
The organization may need to:
- analyze sent messages and data that may have been accessed;
- communicate with affected individuals, customers and partners;
- document the incident and the decisions made;
- assess applicable privacy obligations;
- coordinate IT, legal, executive, communications and cyber insurance teams.
The key takeaway is that resolving the technical compromise does not necessarily mean the incident is over.
Moving From a One-Time Configuration to a Managed Security Model
Controls That Turn a Potential Incident Into a Managed Event
In the scenario presented, several controls can help prevent a phishing attempt from becoming a widespread compromise. These include phishing-resistant authentication, risk-based Conditional Access, application controls, device compliance, appropriate logging and a timely response.
The goal is not to claim that attacks will disappear. It is to reduce their likelihood of success, limit their spread and accelerate the response before the organization has to manage a crisis involving customers and partners.
Measuring Progress With Microsoft Secure Score
Microsoft Secure Score can help you track changes in your security posture, although it does not replace a complete risk assessment.
This indicator may also be requested during certain cyber insurance or vendor assessment processes. It can help track improvements, document implemented controls and support discussions with stakeholders.
Need Experts to Simplify Your Security?
Tenant Security as a Prerequisite for AI Adoption
Microsoft Copilot and other artificial intelligence agents rely on the identities, permissions and data already present in Microsoft 365. If access is too broad or data is poorly governed, AI can amplify an existing issue by accessing, summarizing, creating or modifying content beyond the intended use.
Before authorizing an AI agent, the organization should clarify:
- the business need and scope of the use case;
- the data and workspaces the agent can access;
- permissions to read, create, modify or send content;
- where and under what conditions the data will be processed;
- auditing, monitoring and access revocation mechanisms;
- whether the required features are already included in existing licences.
AI governance is therefore directly connected to cybersecurity governance. The goal is not to slow adoption, but to make it more informed, documented and controlled.
Questions We Answered During Our Webinar
Is a functional Microsoft 365 tenant necessarily secure?
Is multifactor authentication enough to protect Microsoft 365?
Why are Microsoft 365 identities targeted so frequently?
How can an organization strengthen Microsoft 365 tenant security over time?
Why should Microsoft 365 be secured before deploying Copilot or another AI agent?
Are You Ready to Assess Your Microsoft 365 Environment?
The question is not only whether your organization will be targeted. It is whether you have the controls, logs and processes required to prevent an attempt from becoming a crisis.
Precicom can help you assess your Microsoft 365 tenant, prioritize gaps and plan a gradual improvement in your security posture. The recording is not shared publicly. Anyone interested in the content can contact our team.
Stay tuned for upcoming events!
Our team can help you assess your current environment, identify opportunities for transformation, and implement a solution aligned with your organization’s needs. To schedule a personalized presentation, contact us today and explore our upcoming events.
Martin Dagnault is Director of Cybersecurity at Precicom. With more than 20 years of experience in IT and cybersecurity, he helps organizations assess their maturity, manage their security posture and prepare for cyberattacks.Martin Dagnault is also involved in training and raising awareness in information security, combining a pragmatic approach with an understanding of the specific threats each client faces.
Availability
Security
Performance
Compliance
Ces contenus pourraient vous intéresser
Looking for digital efficiency?
Our solutions are delivered in partnership with the industry’s top providers. The organizations that trust us know they’re working with certified IT specialists who understand their needs. They can count on a strategic technology partner, allowing them to focus on what matters most, their core business.
We combine our business acumen, expertise, and knowledge to optimize, secure, and expand digital environments. We push the limits of technology to exceed expectations.
We are Precicom.